Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-07 ยท updated: 2026-09-07 ยท tags: [incident, router, ssh, exposure, exploitation, edge-device] ยท confidence: high ยท affected_sectors: [technology, energy, government] ยท au_impact: true

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

CERT Polska published an attack warning (5 September 2026) describing attackers gaining full administrative control of MikroTik routers whose Secure Shell (SSH) service is reachable from the internet, with no authentication required. Successful attacks date to at least 2 September; no victim count or attacker identity had been published at the time.

Attribute Detail
Date From at least 2 September 2026
Vector Internet-exposed SSH with no authentication
Product MikroTik RouterOS
Fix RouterOS 6.49.21, 7.23.4, 7.24.2 (7.23.5 on the long-term channel to address a regression)
Source CERT Polska โ€” Tier 1/4

MikroTik's security update fixes the issue, and CERT recommends immediate installation followed by a check for unauthorised configuration changes. Home devices with MikroTik's default firewall rules intact are not exposed because public access to management ports is blocked by default. The episode underscores the ongoing risk of internet-exposed management services on edge devices โ€” a recurring theme across the KEV cadence and NCSC UK's guidance on edge-device hygiene.

Related Pages

Source